Impact
The RS9116W/SiWx917 wireless chip can be made to become unresponsive to normal traffic when it receives an unencrypted "pause encryption request" packet. The vulnerability is a case of insufficient access control, which allows an attacker to trigger a denial‑of‑service, damaging availability but not confidentiality or integrity.
Affected Systems
The weakness affects the Silabs WiseCnnect product line that incorporates the RS9116W or SiWx917 radio ASIC. No specific firmware or hardware revisions are listed, meaning all devices that use those chips are vulnerable until a patch is deployed.
Risk and Exploitability
The CVSS base score of 7.1 shows high severity, yet the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating limited evidence of widespread exploitation. Attackers would need to deliver the malformed pause encryption request to the target device; the description implies the packet must reach the radio controller, so the likely vector is via the device’s wireless interface or a connected wired interface. If an adversary can transmit such packets, the device will cease normal operation, causing a denial of service to all applications relying on the chip.
OpenCVE Enrichment